CRAnotify Documentation

Supplier portal

An importer has to collect documentation, declarations and bills of materials from the upstream manufacturer. That is usually done by email, and the result is a folder of attachments nobody can trace any more. Here the supplier uploads them, in a portal that shows very little, and every document arrives marked with who brought it and when. The supplier states; verifying is your job.

Two screens, and a boundary between them

Your panel/fornitori, inside the application. From Products, the Suppliers button. It is reserved to the organisation's administrators: inviting an outsider to read your products' documentation is not an operational gesture.
The supplier's portal/fornitore?t=…, at an address separate from the application's. Whoever enters has no account, no session and does not belong to your organisation: they have a link with a token, like anyone opening the public reporting form.

The link to hand to the supplier is composed by the panel: copy it and send it as it is. Do not rebuild it by hand.

Inviting a supplier

FieldWhat to enter
Name (required)How you will recognise this supplier in the list.
Address (required)A valid email address. It is how you know who you gave access to.
TypeComponent supplier, upstream manufacturer, importer, distributor, evidence provider. A closed list.
Shared products (at least one)Active managed products only, and only yours. An invitation with no products gives access to nothing and is refused.
Duration7, 30, 90 or 180 days.

The token appears once only. Of that link the system keeps only its fingerprint: it does not reach a log, a registry row, or an email we can re-read. If it is lost it cannot be recovered — revoke the invitation and issue another. That is the intended behaviour, not a limitation.

A variant is not shared on its own, and an archived product is no longer in the active perimeter: both stay out of the shareable list.

Asking for a document

On any active invitation you can open a request: a product among the shared ones and a line of text saying what you need. The request appears in the supplier's portal under "What has been asked of you", and when they deposit a document answering that request the state advances by itself to document received — and stops there.

awaiting supplierThe request is open and nobody has deposited anything yet.
document receivedSomething arrived. It does not say it is enough.
to be reviewedYou set it: the document needs looking at.
reviewedYou set it: a person looked at it and it is fine for you.
information missingYou set it: more is needed. The request becomes open again for the supplier.

Only your organisation writes the last three. There are no states such as "manufacturer compliant": that is a conclusion, and it does not come out of a portal.

What arrives is quarantined

A document deposited by a supplier is a file sent by an outsider, and it gets the same treatment as attachments from the public reporting form.

Allowed typesPDF, PNG, JPEG, text or e-mail. The type is decided from the content, not from the extension.
SizeUp to 5 MB per file.
Reference requiredIt is how the supplier will find the document again and how whoever reviews it will cite it.
DownloadFrom your panel, always as an attachment and never rendered in the page.
Upload brakeA token is a secret, but a stolen token must not be able to fill a disk.

An uploaded document is not an accepted document. What arrives is born "to be reviewed" and no path on this surface moves it to "reviewed": that step is a gesture by a person in your organisation. That is how the Regulation distributes responsibilities, and software that compressed them would move them onto whoever does not hold them. See CRA controls and evidence.

What the supplier sees

Their name, your organisation's name, the expiry date of the access, the products you shared with them, the requests assigned to them, and what they uploaded themselves. Nothing else: not the product register, not the cases, not the other suppliers, not the registry. The portal is not indexable and is not cached.

An unknown, expired or revoked link gets the same answer: "this link does not open anything". Distinguishing the three cases would tell whoever is trying whether a token ever existed.

Revoking

The revoke button closes the door immediately, not at the token's expiry: from the next use that link does not pass. Access removed "sooner or later" is not access that has been removed. Documents already deposited remain — they are dossier material — and stay downloadable from your panel.

In the list every invitation carries its own state — active, revoked or expired — and revoked invitations stay visible: you need to be able to say "this access is closed", and who closed it.

What goes into the registry

Issuing an invitation, revoking it, opening a request, updating it, and the arrival of a document each leave a row in the activity registry. The plaintext token and the supplier's address do not: the first is a secret, the second is personal data that an evidence package does not need.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu